PT-2017-17148 · Asus · Asus Rt-N12+ Pro+20

Bruno Bierbaumer

·

Publicado

2017-03-09

·

Atualizado

2019-10-03

·

CVE-2017-6549

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers versions prior to 3.0.0.4.380.7378 RT-AC68W routers versions prior to 3.0.0.4.380.7266 RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers versions prior to 3.0.0.4.380.9488 Asuswrt-Merlin firmware versions prior to 380.65 2
Description A session hijack issue in httpd on various ASUS routers allows remote attackers to steal any active admin session by sending specific HTTP headers, including cgi logout and asusrouter-Windows-IFTTT-1.0.
Recommendations For ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers, update the firmware to version 3.0.0.4.380.7378 or later. For RT-AC68W routers, update the firmware to version 3.0.0.4.380.7266 or later. For RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers, update the firmware to version 3.0.0.4.380.9488 or later. For Asuswrt-Merlin firmware, update to version 380.65 2 or later. As a temporary workaround, consider restricting access to the cgi logout and asusrouter-Windows-IFTTT-1.0 HTTP headers until a patch is available.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6549

Produtos afetados

Asus Rt-Ac1750
Asus Rt-Ac1900P
Asus Rt-Ac3200
Asus Rt-Ac51U
Asus Rt-Ac53U
Asus Rt-Ac66U
Asus Rt-Ac68U
Asus Rt-Ac750
Asus Rt-Ac87U
Asus Rt-N11P
Asus Rt-N11P B1
Asus Rt-N12+
Asus Rt-N12+ B1
Asus Rt-N12+ Pro
Asus Rt-N12E B1
Asus Rt-N300
Asus Rt-N300 B1
Asus Rt-N56U
Asus Rt-N600
Asus Rt-N66U
Asuswrt-Merlin